Most branded merchandise vendors say they are "SOC 2 compliant" and hope you do not ask the follow-up question. The follow-up question is the entire conversation. This is a plain-language read on what SOC 2 actually is, what your GRC team should be asking for, and what separates a vendor who takes data seriously from one using the acronym as a trust badge.
What SOC 2 actually is.
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA). It is not a certification in the ISO sense. It is an auditor's opinion, issued after examining a service organization's controls against the AICPA Trust Services Criteria.
The Trust Services Criteria cover five domains:
- Security. Controls protecting the system against unauthorized access. This is the only required domain. If a vendor has "a SOC 2" without specifying which criteria, it almost always means Security only.
- Availability. Controls ensuring the system is available for operation and use as committed or agreed.
- Processing Integrity. Controls ensuring system processing is complete, valid, accurate, timely, and authorized.
- Confidentiality. Controls protecting information designated as confidential.
- Privacy. Controls governing the collection, use, retention, disclosure, and disposal of personal information.
A SOC 2 report is issued by a licensed CPA firm after an audit. The report is not public. The vendor owns it and shares it under NDA with customers and prospects.
Reference: the AICPA maintains the current Trust Services Criteria at aicpa-cima.com.
Type I versus Type II.
This is the distinction that matters most for enterprise procurement, and it is the one most vendors gloss over.
Type I.
A Type I report is a point-in-time attestation. The auditor examines whether the controls are designed appropriately and in place on a specific date. That is it. A Type I report tells you the vendor had the controls documented on, say, March 31, 2025. It does not tell you whether those controls operated effectively before or after that date.
Type I is often the first step in a vendor's SOC 2 program. Many mid-sized vendors get there and stop. A Type I alone is a signal that the vendor is in progress, not that the program is mature.
Type II.
A Type II report is the enterprise standard. The auditor examines whether the controls operated effectively over a sustained observation period, typically 6 to 12 months. The auditor tests the controls, reviews evidence, interviews personnel, and issues an opinion on whether the controls did their job over that window.
Type II is what GRC teams at enterprise buyers actually require. It is the difference between "we have written policies" and "the auditor watched the policies operate for a year and signed off."
If a vendor says they are "SOC 2 compliant" and cannot produce a current Type II report with at least a 6-month observation period, treat it as if they are in progress, not attested. Type II is the bar. Anything below it is a signal, not a decision.
Why this matters for a branded program.
Branded merchandise and workwear programs run on data that used to live in a spreadsheet and now lives in a platform.
- Employee data. Names, addresses, sizes, roles, job codes, sometimes employee IDs, sometimes hire dates. This is PII by any definition.
- Order data. Purchase history, payment data, shipping addresses, approvals tied to named managers.
- Payment data. Credit card tokens, ACH details, corporate card authorizations. PCI scope overlaps here.
- Enterprise system integration. Most programs integrate with HRIS, ERP, SSO, SAML. That integration means the vendor's platform has a credential or a token that reaches into your stack.
- Compliance documentation. For FR and PPE programs, per-worker, per-garment certification data lives in the vendor's system. That data gets pulled during audits.
A data breach at a branded merchandise vendor is not a low-stakes event. It is a PII breach, a potential payment data breach, and a credential exposure back into your ERP. GRC teams that take vendor risk seriously apply the same standard to merchandise vendors that they apply to SaaS platforms handling sensitive data.
What a SOC 2 Type II report actually contains.
A SOC 2 Type II report is typically 50 to 150 pages. The structure follows a consistent pattern.
- Auditor's opinion. The front of the report. The auditor's qualified or unqualified opinion on whether controls operated effectively over the observation period.
- Management's assertion. The service organization's written statement about its system and the controls in place.
- System description. Plain-language description of the services, infrastructure, data flows, and boundaries of the system in scope. This is where you learn what the report actually covers.
- Control descriptions. The full list of controls grouped by Trust Services Criteria. Each control has a description and a test procedure.
- Test results. The auditor's observations, including any exceptions noted during testing.
- Complementary user entity controls. Controls the customer (you) must implement for the vendor's controls to be effective. This section is small and often ignored, but it tells you what you are on the hook for.
Enterprise GRC teams read the auditor's opinion first, scan the system description to confirm scope, then jump to the test results to look for exceptions.
What to ask a vendor.
Here is the sequence of questions that separates a mature vendor from one using the acronym as a trust badge.
- "Do you have a current SOC 2 Type II report?" The answer is yes or no. No hedging. If yes, ask when the observation period ended.
- "Which Trust Services Criteria are in scope?" Security only, or Security plus one or more of Availability, Processing Integrity, Confidentiality, Privacy. More criteria in scope is a signal of maturity.
- "What is the observation period?" 6 months is the floor. 12 months is standard for mature programs. Observation periods that ended more than 12 months ago are stale.
- "Who is the auditor?" A recognized CPA firm (any of the Big Four, a top-20 regional, or a SOC-specialized firm like Schellman, A-LIGN, Prescient) is a good signal. A firm nobody has heard of is worth investigating.
- "Were there exceptions in the most recent report?" Mature vendors answer this directly. Exceptions happen. What matters is severity and remediation.
- "Can I see the full report under NDA?" The answer should be yes. A vendor that refuses to share the report under NDA does not have a report or has something to hide.
- "What is in scope for your SOC 2 versus your hosting provider's SOC 2?" The red flag. Many vendors point to AWS, Azure, or GCP SOC 2 reports as their own. That is not how it works.
The red flags.
After a decade of enterprise procurement conversations, these are the signals that tell you a vendor is not where they claim to be.
- "We're SOC 2 compliant" with no report. "Compliant" is not a term of art in the SOC 2 world. Attested, yes. Certified, no. A vendor using "compliant" loosely usually does not have a Type II report.
- Pointing at the hosting provider's SOC 2. AWS has a SOC 2. That does not transfer to the vendor running their application on AWS. The vendor's own controls have to be audited separately.
- A Type I instead of a Type II. Not a red flag on its own if the vendor is actively moving to Type II, but a Type I that has sat unchanged for 18 months is a signal the program stalled.
- A report older than 12 months. Observation periods roll. A report from 2023 does not tell you about 2025 operations. Mature vendors run annual observation cycles and keep the report current.
- Refusing to share the report under NDA. The full report is confidential. It is not so confidential that the vendor cannot share it with a prospective enterprise customer under a standard mutual NDA. Refusal here means something.
- A "bridge letter" with no plan to re-attest. Bridge letters bridge the gap between observation periods. They are fine for 60 days. A vendor leaning on a bridge letter for six months is a vendor that has not scheduled the next audit.
What Brand Junkie's SOC 2 covers.
I will be specific here because the whole point of this article is that vague is a red flag.
- Scope. The Brand Junkie platform, including the Salesforce Commerce Cloud stores we run for clients, the order management layer, the data integrations with client HRIS and ERP systems, and the supporting infrastructure.
- Criteria. Security, Availability, and Confidentiality Trust Services Criteria.
- Type. Type II.
- Observation period. Rolling 12-month cycle.
- Auditor. A recognized SOC-specialized CPA firm. Named in the report.
- Availability. The full report is available under mutual NDA to any prospective enterprise customer. We do not hide it behind paywalls or gatekeepers.
If you are evaluating us against another vendor, that is what your GRC team should be asking for on both sides. Apples to apples.
The question to bring to vendor review.
When you are evaluating a branded merchandise or workwear vendor for an enterprise program, the SOC 2 question is not "do you have one." It is "do you have a current Type II report, which Trust Services Criteria are in scope, and can I see it under NDA."
Three sentences. If the vendor can answer all three in the same meeting, that is a mature partner. If any of the three turns into a hedge, the vendor is telling you where the program actually is.
Written from three decades running enterprise programs that have to pass GRC review. Brand Junkie runs the only branded merchandise and workwear program in the category on a SOC 2 Type II attested platform with Salesforce Commerce Cloud at its core.